<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>SBOM on Subhash Dasyam</title><link>https://subhash.net/tags/sbom/</link><description>Recent content in SBOM on Subhash Dasyam</description><generator>Hugo</generator><language>en</language><lastBuildDate>Wed, 21 May 2025 22:56:28 +0400</lastBuildDate><atom:link href="https://subhash.net/tags/sbom/index.xml" rel="self" type="application/rss+xml"/><item><title>Container Receipts: The Missing Ingredient in Your Security Recipe : Container SBOMs</title><link>https://subhash.net/posts/container-receipts-missing-ingredient/</link><pubDate>Wed, 21 May 2025 22:56:00 +0400</pubDate><guid>https://subhash.net/posts/container-receipts-missing-ingredient/</guid><description>&lt;h3 id="the-mystery-of-the-missing-sbom">The Mystery of the Missing SBOM&lt;/h3>
&lt;p>It&amp;rsquo;s 3 AM when the alert comes in. A critical vulnerability has been found in a library used across the company&amp;rsquo;s microservices architecture. The security team needs to know: Which containers are affected? When were they built? Who built them? And most importantly - can they prove to auditors that the fix was complete?&lt;/p></description></item></channel></rss>